الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 26. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

marketbuffalo[.]click

“Personal Banking | M&T Bank”

حكم التهديد حرجة 100/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 26/91 URLQuery threat systems: 6 alerts PhishStats feed match انتحال العلامة التجارية: Mtbank
OTX: 3 refs 16/06/2026 Mtbank 1 Report Sent

ملخص الأدلة

حرج
Evidence score
100/100

The domain marketbuffalo.click was identified as a generic phishing threat, specifically designed to impersonate M&T Bank's personal banking login page. Currently offline, this domain posed a high risk to users who may have been tricked into entering sensitive credentials. The site's title, "Personal Banking | M&T Bank," closely mimicked the legitimate bank's interface, making it a convincing lure for unsuspecting victims.

Technical analysis reveals that marketbuffalo.click was registered through DYNADOT LLC on May 27, 2026, and resolved to IP address 31.56.229.111. It was flagged by 26 out of 95 security vendors on VirusTotal, indicating broad recognition as malicious. Additionally, it appeared on one security blocklist and was found in three AlienVault OTX threat intelligence pulses. Google Safe Browsing also flagged the domain for phishing. The SSL certificate was issued by Let's Encrypt (R12), which is commonly abused by malicious actors due to its free and automated issuance.

Given the domain's high risk level and its impersonation of a major financial institution, users are strongly advised to avoid any interaction with marketbuffalo.click. PhishDestroy recommends that individuals who may have visited the site change their M&T Bank passwords immediately and enable multi-factor authentication. Always verify URLs directly by typing the bank's official web address into the browser, and report any suspicious domains to security authorities.

لقطة الأدلة المرسلة

أُرسل
سجلات الدفتر
1
معرّف القضية
PD-20260617-304E80
ملف PDF
دليل PDF
النص الكامل للدليل
Registrar: Dynadot LLC / Dynadot Inc (United States)
Policy Violations: Acceptable Use forbids illegal content; Spam & Abuse Policy prohibits phishing, fraud, malware; Dynadot may disable DNS and suspend domains
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
VirusTotal
VirusTotal
26 det.
URLQuery
URLQuery
6 threat alerts
OTX references
شهادة TLS
Let's Encrypt / R12 11d
العمر
3 mo New
الحالة المرصودة
المحتوى غير متوفر HTTP 502
PhishDestroy
قائمة الإتلاف
مدرج
Reports Sent
1

Data Coverage

VirusTotal 26 / 91 URLQuery 6 threat-system alerts PhishStats feed match · 1 record OTX 3 community references رادار CF no data URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 11d WHOIS 3 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
Threat Detection Systems 6 alerts
Detection System Indicator Verdict Alert
DigiCert UltraDNS marketbuffalo.click malicious Sinkholed
Quad9 DNS marketbuffalo.click malicious Sinkholed
Hagezi Threat Feed marketbuffalo.click malicious Sinkholed
Cloudflare DNS marketbuffalo.click malicious Sinkholed
DNS4EU marketbuffalo.click malicious Sinkholed
OpenDNS marketbuffalo.click phishing Phishing Block

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
14/14

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

لقطة محفوظة

عنوان الصفحة
Personal Banking | M&T Bank
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt / R12 · valid for 11 days

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing brand: Mtbank report ↗
Google Safe Browsing تم وضع علامة عليها Social engineering checked 17/06/2026
PhishStats Feed match 1 record checked 17/06/2026
الخادم / ASN nginx/1.30.0 · AS56971 AS56971 Cloud
سمعة عنوان IP IP abuse confidence 0/100 0 reports checked 16/06/2026
مسجّل النطاق DYNADOT US(US)
جهة الإبلاغ عن إساءة الاستخدامabuse@cloudbackbone.net, abuse@dynadot.com
البحث في قاعدة بيانات WHOISICANN RDAP لـ marketbuffalo.click →
عنوان IP 31.56.229.111 US
الموقع الجغرافيUS Kansas City, US
الشبكةAS56971 · CGI GLOBAL LIMITED
التسجيلتم إنشاؤه 27/05/2026 (78d · New) Expires 27/05/2027
حالة HTTP502 Error
الوقت حتى أول تعذّر للوصول 39h
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف16/06/2026
Submitted URLhttp://marketbuffalo.click/log-in
خوادم الأسماءns1.dyna-ns.netns2.dyna-ns.net
بصمة TLS
رصد TLSصالح منذ 27/05/2026فُحص في 16/06/2026
الأسماء البديلة لموضوع TLSwww.marketbuffalo.click
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

26 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed
Criminal IP
alphaMountain.ai
BitDefender
Chong Lua Dao
Cluster25
CRDF
CyRadar
Ermes
ESET
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Google Safebrowsing
Gridinsoft
كاسبرسكي
LevelBlue
Lionic
MalwareURL
نتكرافت
PhishLabs
Seclookup
SOCRadar
سوفوس
VIPRE
Webroot

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/marketbuffalo.click"
  title="PhishDestroy threat report for marketbuffalo.click"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.